Stream Corruption Vulnerability in Spring Framework by VMware
CVE-2026-47890

9.8CRITICAL

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-47890?

CVE-2026-47890 is a vulnerability identified in the Spring Framework, specifically affecting the Spring MVC and WebFlux applications. This vulnerability relates to stream corruption that can occur when Server-Sent Events (SSE) are utilized along with view fragments. The affected versions include Spring Framework 7.0.0 to 7.0.8 and 6.2.0 to 6.2.19. The implications of this vulnerability are significant as it can potentially disrupt the data streaming processes within applications that rely on the Spring Framework, compromising the integrity of data sent from the server to the client. Organizations using these frameworks could face challenges that hinder application performance and reliability, leading to a degradation of user experience and operational efficiency.

Potential impact of CVE-2026-47890

  1. Data Integrity Risks: Exploitation of this vulnerability could lead to corrupted data streams, resulting in erroneous information being delivered to end-users or being processed by applications. This can severely affect application reliability and user trust.

  2. Application Downtime: The integrity issues caused by this vulnerability may lead to increased application errors and crashes, potentially resulting in downtime. Organizations could experience service interruptions that negatively impact their operational capabilities and customer satisfaction.

  3. Increased Maintenance Overhead: Organizations may incur additional costs and resource allocation for diagnosing and addressing the consequences of the vulnerability. The need for immediate patches and fixes can divert IT staff from other critical projects, thus affecting overall productivity.

Affected Version(s)

Spring Framework 7.0.0 <= 7.0.8

Spring Framework 6.2.0 <= 6.2.19

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.